
ES-2024 Series User’s Guide
171
C
H A P T E R
23
IP Source Guard
Use IP source guard to filter unauthorized ARP packets in your network.
23.1 IP Source Guard Overview
IP source guard uses a binding table to distinguish between authorized and unauthorized ARP
packets in your network. A binding contains these key attributes:
• MAC address
• VLAN ID
• IP address
• Port number
When the Switch receives an ARP packet, it looks up the appropriate MAC address, VLAN
ID, IP address, and port number in the binding table. If there is a binding, the Switch forwards
the packet. If there is not a binding, the Switch discards the packet.
The Switch builds from information provided manually by administrators (static bindings).
IP source guard consists of the following features:
• Static bindings. Use this to create static bindings in the binding table.
• ARP inspection. Use this to filter unauthorized ARP packets on the network.
23.1.1 ARP Inspection Overview
Use ARP inspection to filter unauthorized ARP packets on the network. This can prevent
many kinds of man-in-the-middle attacks, such as the one in the following example.
Figure 94
Example: Man-in-the-middle Attack
Summary of Contents for ES-2024 Series
Page 2: ......
Page 8: ...Safety Warnings ES 2024 Series User s Guide 8...
Page 20: ...Table of Contents ES 2024 Series User s Guide 20...
Page 28: ...List of Tables ES 2024 Series User s Guide 28...
Page 30: ...30...
Page 38: ...Chapter 2 Hardware Installation and Connection ES 2024 Series User s Guide 38...
Page 44: ...Chapter 3 Hardware Overview ES 2024 Series User s Guide 44...
Page 46: ...46...
Page 56: ...Chapter 4 The Web Configurator ES 2024 Series User s Guide 56...
Page 66: ...Chapter 6 Tutorials ES 2024 Series User s Guide 66...
Page 86: ...86...
Page 98: ...Chapter 9 VLAN ES 2024 Series User s Guide 98...
Page 104: ...Chapter 11 Static Multicast Forwarding ES 2024 Series User s Guide 104...
Page 136: ...Chapter 18 Port Authentication ES 2024 Series User s Guide 136...
Page 170: ...Chapter 22 AAA ES 2024 Series User s Guide 170...
Page 185: ...185 PART IV IP Application Static Route 187 Differentiated Services 191 DHCP 195...
Page 186: ...186...
Page 190: ...Chapter 25 Static Route ES 2024 Series User s Guide 190...
Page 202: ...202...
Page 226: ...Chapter 29 Access Control ES 2024 Series User s Guide 226...
Page 228: ...Chapter 30 Diagnostic ES 2024 Series User s Guide 228...
Page 232: ...Chapter 31 Syslog ES 2024 Series User s Guide 232...
Page 242: ...Chapter 33 MAC Table ES 2024 Series User s Guide 242...
Page 248: ...248...
Page 256: ...Appendix A Product Specifications ES 2024 Series User s Guide 256...
Page 268: ...Appendix C Legal Information ES 2024 Series User s Guide 268...